CVE-2021-41864
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multipl
CVSS
7.8
Alto
EPSS
0.4%
p35
KEV
—
Exploit Today
10
0-100
Publicado: 2 oct 2021 · Última mod.: 5 ago 2026 · CWE-190
0.4%EPSS · 30 días0.4%
2026-08-262026-09-23
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
- cdn.kernel.orghttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.12
- git.kernel.orghttps://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=30e29a9a2bc6a4888335a6ede968b75cd329657a
- github.comhttps://github.com/torvalds/linux/commit/30e29a9a2bc6a4888335a6ede968b75cd329657a
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7BLLVKYAIETEORUPTFO3TR3C33ZPFXQM/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAT3RERO6QBKSPJBNNRWY3D4NCGTFOS7/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYKURLXBB2555ASWMPDNMBUPD6AG2JKQ/
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20211029-0004/
- www.debian.orghttps://www.debian.org/security/2022/dsa-5096
- cdn.kernel.orghttps://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.12
- git.kernel.orghttps://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf.git/commit/?id=30e29a9a2bc6a4888335a6ede968b75cd329657a
- github.comhttps://github.com/torvalds/linux/commit/30e29a9a2bc6a4888335a6ede968b75cd329657a
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/12/msg00012.html
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7BLLVKYAIETEORUPTFO3TR3C33ZPFXQM/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LAT3RERO6QBKSPJBNNRWY3D4NCGTFOS7/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SYKURLXBB2555ASWMPDNMBUPD6AG2JKQ/
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20211029-0004/
- www.debian.orghttps://www.debian.org/security/2022/dsa-5096
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-935779.9 CRÍ—
———GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.12hCVE-2026-66687.5 ALT—
——0Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker to cause a denial of service. Sufficiently large input makes the buffer size computation overflow, leaving the growth loop unable to terminate. Because PgBouncer serves all clients from a single process, this saturates a CPU core and stalls every pooled connection until the process is killed. Both unauthenticated and authenticated code paths can reach the overflow.17hCVE-2026-966744.4 MED—
——0alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.16hCVE-2026-966116.9 MED—
——0FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_MAX to become negative. In read_image_grid(), accumulating these values causes signed integer overflow (undefined behavior per C17 section 6.5), which on x86 wraps to a small positive value, bypassing downstream validity checks.21hCVE-2026-892775.5 MED16.8%
——5CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page.21hCVE-2026-18462—1.5%
——0Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allows Shared Resource Manipulation. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*.2d